T1106 Native API
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Turla Group Named Pipescriticaltest · windows
- BPFDoor Abnormal Process ID or Lock File Accessedhightest · linux
- HackTool - CobaltStrike BOF Injection Patternhightest · windows
- HackTool - HandleKatz Duplicating LSASS Handlehightest · windows
- HackTool - RedMimicry Winnti Playbook Executionhightest · windows
- HackTool - WinPwn Executionhightest · windows
- HackTool - WinPwn Execution - ScriptBlockhightest · windows
- Potential WinAPI Calls Via CommandLinehightest · windows
- Potential WinAPI Calls Via PowerShell Scriptshightest · windows
- Suspicious Mshta.EXE Execution Patternshightest · windows
- Potential Binary Proxy Execution Via Cdb.EXEmediumtest · windows
- Potential Direct Syscall of NtOpenProcessmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.